Okta analyzed thousands of real social-engineering incidents and found most account takeovers still rely on stealing passwords and then bypassing MFA through push prompts or one-time codes. Okta described multiple campaigns where attackers phished credentials and then talked victims into using weaker login methods, including a ruse claiming a hardware security key “is not working.”
How the attack worked
Okta analyzed roughly 6,000 real social-engineering events and found a consistent pattern behind most account takeovers. Attackers first steal a password through phishing, then work to defeat whatever MFA protection is in place. In one campaign starting in August 2026, a phishing kit stole both passwords and one-time login codes. The kit presented a fake login window with an invented excuse, telling victims their hardware security key was not working and urging them to use a one-time passcode instead. Once attackers gained access, they changed the victim's MFA enrollment to point at attacker-controlled infrastructure, letting them retain control of the account even if the original credentials were later reset.
Okta also described two other campaigns that used different entry points. One in mid-2025 used Slack direct messages to direct victims to phishing sites, and another in 2023 began with text messages. Both ultimately funneled victims toward a fake login page designed to harvest credentials and authentication codes.
Why it succeeded
The data shows MFA alone is not a guaranteed defense. Okta found that 58% of account takeovers involved compromised push notifications, 36% involved theft of app-based codes, and 22% involved theft of SMS-based codes. A password theft combined with push-notification subversion appeared in 47% of takeovers. These weaker authentication methods are phishable: a convincing pretext and a realistic fake login page are often enough to get a victim to hand over a code or approve a push, especially when the attacker frames it as the only option because a stronger method
Key findings
- Okta analyzed roughly 6,000 social-engineering events and found 87% of account takeovers involved compromised passwords.
- Many takeovers also involved MFA bypass/abuse: 58% involved compromised push notifications, 36% involved theft of app-based codes, and 22% involved theft of SMS-based codes.
- A common pattern was password theft plus push-notification subversion (47% of account takeovers).
- Okta described a campaign (starting Aug. 2026) where a phishing kit stole both passwords and one-time login codes and used a ruse to push victims away from phishing-resistant authentication.
- After gaining access, attackers changed victims’ MFA enrollments to attacker-controlled infrastructure.
- Okta also described campaigns using Slack direct messages (mid-2025) and text messages (2023) to send victims to phishing sites.
Who’s being targeted
- Commonly targeted roles: All employees, IT/Identity administrators, Security operations, Slack users, Finance and other high-risk business users.
- Affected industries: Multiple industries (enterprise users of MFA/SSO).
- Attack channels: website, slack, smishing.
- Impersonated: Organization login/SSO page (fake lookalike), Someone contacting the user via Slack DM (not specified in article), Sender via SMS/text message (not specified in article).
Red flags to watch for
- Login page discourages using a security key and pushes a weaker method “instead”
- Unexpected request to re-authenticate and provide a one-time code
- URL/domain mismatch or unusual sign-in flow compared to the normal SSO experience
- Unsolicited Slack DM with a login link
- Pressure to click immediately instead of using a known bookmark/app
- Link goes to an unfamiliar domain or prompts unexpected MFA steps
- Unexpected security/verification text with a link
- Sense of urgency to act immediately
- Link does not match official corporate domains
Frequently asked questions
How do phishers get victims to bypass MFA?
Okta found attackers phish passwords and then use pretexts, such as claiming a hardware security key is not working, to convince victims to use a weaker method like a one-time passcode instead.
What percentage of account takeovers involved compromised passwords?
Okta analyzed roughly 6,000 social-engineering events and found that 87% of account takeovers involved compromised passwords.
Does phishing-resistant authentication actually help?
Yes. Okta found that requiring phishing-resistant authentication would have stopped 88% of the account takeover attempts in its dataset.
What happens after attackers gain account access?
Okta described attackers changing victims' MFA enrollments to their own infrastructure after gaining access, allowing them to maintain control of the account.
Read the video transcript
You log in with your hardware security key… and the screen says, “Your hardware key is not working. Use a one-time passcode instead.” Okta saw this for real: a phishing kit that steals your password and your one-time code, then locks you out by changing your MFA. The whole trick is pushing you off your security key onto weaker MFA. Sometimes it starts with a Slack DM: “Hey, can you sign in here to review this?” You click, see a familiar-looking login, and it suddenly insists on a one-time code instead of your usual key or normal SSO flow. If any login page or message tells you your hardware key “is not working” and pushes you to a one-time code, stop. Don’t switch methods, open your normal SSO bookmark or app and sign in from there instead.